Imdr.

Privacy Policy

Registered Foreign Patient Attraction Business

Registration No.: A-2023-01-01-4911 (Korea Health Industry Development Institute, Medical Service Act Article 27-2)

Imdr LLC (hereinafter the "Company") values the personal information of its users and complies with the personal information protection provisions under applicable laws, including the Act on Promotion of Information and Communications Network Utilization and Information Protection and the Personal Information Protection Act, and continuously strives to protect the personal information of its members. Through this Privacy Policy, the Company will do its best to ensure that the personal information of users is not misused or leaked, and will inform users of the purposes and methods for which the personal information they provide is used, as well as the measures taken to protect personal information. This Privacy Policy may be amended in line with changes in government laws and guidelines, or to provide better services, so users are advised to check its contents from time to time when visiting the site. Where the Company revises this Privacy Policy, it will announce the change through a notice on the website or through individual notification. This Privacy Policy does not apply to sites linked from the Company's official site, and the Company assumes no responsibility for any information exposed due to reasons attributable to the member.

1. Personal Information Collected and Purposes of Use

The Company collects personal information with the user's prior consent for membership registration, customer support, and the provision of various services. Personal information is not used for purposes other than those of collection and use stated below, and where the purpose of collection or use changes, the Company will take necessary measures such as obtaining separate consent in accordance with the Personal Information Protection Act.

a. Information collected during membership registration

Method of collection: The user consents to the collection of personal information and enters the information directly during registration.

Items collected: ID (email or SNS account), password, name, mobile phone number, gender, age, nationality, address, signature

Purpose of use: Provision of membership services, marketing activities, and notification of updates and announcements

b. Finding a hospital

Method of collection: Consent to the Location-Based Services Terms of Use

Items collected: User location (latitude, longitude)

Purpose of use: To enable use of the hospital reservation service

c. Medical treatment, registration, and reservations

Method of collection: The user consents to the collection of personal information and enters it directly.

Items collected: Name, date of birth, nationality, gender, mobile phone number, name of registered/reserved hospital, date and time of registration, cancellation history, identity verification number (e.g., alien registration number), and personal information of children (under 14) (name, date of birth, gender, mobile phone number, name of registered/reserved hospital, date and time of registration, cancellation history)

Purpose of use: To provide hospital treatment services within the scope permitted by the Medical Service Act and its Enforcement Decree

d. Insurance claims

Method of collection: The user consents to the collection of personal information and enters it directly.

Items collected: Name, date of birth, nationality, gender, mobile phone number, identity verification documents such as passport and alien registration card, medical records, insurer name, insurance contract date, policy number, bank name, bank account

Purpose of use: To provide insurance benefit payment services within the scope permitted by the Medical Service Act and its Enforcement Decree

e. Information collected during use of paid services

Method of collection: Information entered directly by the user on the payment and payment-information registration screens, with consent to the collection of personal information

Items collected: Email, mobile phone number, nationality, insurer information, etc.

Purpose of use: Customer management associated with the use of paid services and provision of information to partner companies

f. Partnership inquiries

Method of collection: The user consents to the collection of personal information and enters partnership-inquiry information directly.

Items collected: Name, mobile phone number, email, hospital address, hospital telephone number

Purpose of use: Customer management and provision of information associated with the use of partnership services

g. Personal information automatically generated and collected during service use

Method of collection: Automatically generated

Items collected: Access IP information, access logs, cookies, service usage records, device identifiers, visit history, etc.

Purpose of use: Identity verification, prevention of fraudulent use, and analysis of usage records to improve services

h. In addition, in the course of participating in marketing events and promotions, information such as name, date of birth, gender, email address, blog address, school, company, and other information necessary for providing and delivering prizes may be collected at the user's option. In such cases, the items collected and purposes of use are separately notified to the member to obtain consent.

2. Provision of Personal Information to Third Parties

Recipient of personal information

Hospitals that have a partnership agreement with Imdr LLC and that provide the reservation service requested by the user for treatment registration/reservation, as listed separately on the Company's website. (Hospital list link)

Purpose of use

For the use of hospital reservation, examination, and treatment services

Personal information provided

Registrant information (self/child): name, date of birth, nationality, gender, mobile phone number, alien registration number

Recipient of personal information

The insurer with which the user is enrolled and to which the user requests an insurance-refund service, as listed separately on the Company's website. (Insurer list link)

Purpose of use

For the use of insurance benefit or insurance-refund application services

Personal information provided

Name, date of birth, nationality, gender, mobile phone number, medical records, insurer name, insurance contract date, policy number

The Company uses the personal information of users only within the scope specified in the purposes of collection and use, and in principle does not use it beyond that scope or provide it to outside parties without the user's prior consent.

However, where it is necessary to share a user's personal information with a partner company to provide quality services, the Company may provide information to a third party within the minimum necessary scope, in which case it will notify the member of the recipient, purpose, items of information provided, and period of use and retention to obtain consent. This excludes cases based on the provisions of laws, or where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for investigative purposes. Users may refuse to consent to the provision of personal information under this section; however, refusal may make it difficult to use certain services that require login.

3. Retention and Use Period of Personal Information

The Company, in principle, retains and uses a user's personal information only during the period in which it provides services to the user. Where a member requests withdrawal of membership or withdraws consent to the collection and use of personal information, where the purpose of collection/use has been achieved or the retention/use period has ended, or where an event such as business closure occurs, the relevant personal information is destroyed without delay. However, where retention is necessary for a certain period under the Company's internal policy to prevent disputes arising from fraudulent use of services, or under the provisions of applicable laws, the information is retained. The personal information retained and the relevant laws are as follows.

ID (email), password, mobile phone number, identity verification documents such as passport and alien registration card

Company internal policy to prevent fraudulent use of services such as abuse of membership registration

Retention period: 1 year after withdrawal of membership

Log records, IP, etc.

Applicable law: Protection of Communications Secrets Act

Retention period: 3 months

Books and supporting documents on all transactions prescribed by tax law

Applicable law: Framework Act on National Taxes

Retention period: 5 years

Records on labeling/advertising

Applicable law: Act on Consumer Protection in Electronic Commerce

Retention period: 6 months

Records on contracts or withdrawal of subscription

Applicable law: Act on Consumer Protection in Electronic Commerce

Retention period: 5 years

Records on payment and supply of goods, etc.

Applicable law: Act on Consumer Protection in Electronic Commerce

Retention period: 5 years

Records on consumer complaints or dispute handling

Applicable law: Act on Consumer Protection in Electronic Commerce

Retention period: 3 years

Where there is separate individual consent from the user, the information is retained for the period agreed to in that individual consent.

4. Procedure and Method of Destroying Personal Information

The Company destroys personal information without delay once the purpose of collection and use has been achieved and the period specified in the retention and use period has elapsed. The Company's procedure and method for destroying personal information are as follows.

Information entered by a user for purposes such as membership registration is, once its purpose has been achieved, moved to a separate database (or a separate document file in the case of paper) and stored for a certain period in accordance with internal policy and other information-protection grounds under applicable laws (see Retention and Use Period), then destroyed. Such personal information is not used for any purpose other than retention unless required by law.

Personal information printed on paper and received documents are shredded or incinerated; personal information stored in electronic file form is deleted using technical methods that make the records irrecoverable.

5. Entrustment of Personal Information Handling

Where necessary for the smooth provision of services, the Company entrusts part of the handling of personal information within the scope of the consented purposes of use. The Company notifies users of the party entrusted with handling personal information (the "trustee") and the details of the entrusted work and obtains consent. The trustees and details of work are as follows.

a. Customer support

Trustee: Kakao Corp., Munja114, Munjaui-sin

Details of work: Sending and receiving SMS and KakaoTalk messages

In addition to the companies entrusted with handling personal information, where there is entrustment of personal information handling due to the provision of additional services, or where there is a change in the details of work, the Company will notify users in advance of the trustee and the details of work through the "Notices" section of the website or application, or through individual contact, and obtain consent.

6. Rights of Users and Legal Representatives and How to Exercise Them

Membership registration of children under the age of 14 (hereinafter "children") is carried out through forms written in plain language that children can easily understand, and consent of the legal representative is always obtained when collecting personal information.

To obtain the consent of the legal representative, the hospital collects minimal information such as the name and contact details of the legal representative from the child, and obtains the legal representative's consent in accordance with the methods set out in this Privacy Policy.

The legal representative of a child may request access to, correction of, and deletion of the child's personal information. If you wish to access, correct, or delete a child's personal information, or contact the person responsible for personal information protection in writing, by telephone, or by fax, the necessary measures will be taken.

The hospital does not provide or share information about children with third parties, and where a legal representative requests correction of errors in personal information collected from a child, the use and provision of the relevant personal information is prohibited until the error is corrected.

Personal information whose retention is mandatory under applicable laws cannot be modified or deleted within the retention period even upon request.

7. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

The Company uses "cookies" that store and frequently retrieve users' information in order to provide appropriate services to visitors of the Company's site. A cookie is a small piece of information that the server (HTTP) used to operate the website sends to the user's computer browser, and is sometimes stored on the hard disk of the user's PC. The Company uses cookies to understand how users (site visitors) visit and use each of Imdr's services and websites, popular search terms, and the scale of usage, in order to provide users with optimized information.

Users have a choice regarding cookie settings. Accordingly, by setting options in their web browser, users can confirm each time a cookie is stored, allow all cookies, or refuse to store all cookies. However, if you refuse to store cookies, you may have difficulty using certain services that require login.

※ How to set whether to allow cookie installation (for Internet Explorer): Tools at the top of the web browser > Internet Options > Privacy

Use of a Web Analytics Tool (Google Analytics)

The Company uses Google Analytics, a web analytics tool provided by Google LLC, to analyze service usage and improve the service. Through cookies, Google Analytics collects and analyzes user behavior such as site visit paths (traffic sources), page views, time on page, and clicks, together with access device and browser information and approximate location (country/city).

In addition, through the Google Signals feature, the Company may collect demographic information such as users' age range, gender, and interests in a statistical, non-identifying form. This information is used solely for analyzing the characteristics of service users, not for ad personalization, and does not identify any specific individual.

Users may refuse Google Analytics data collection by declining analytics cookies in the cookie consent banner shown when accessing this site, or by installing the opt-out browser add-on provided by Google (https://tools.google.com/dlpage/gaoptout). For more details on Google's data processing, please refer to the Google Privacy Policy (https://policies.google.com/privacy).

8. Technical and Administrative Measures for Protecting Personal Information

In handling users' personal information, the Company takes the following technical and administrative measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged.

Technical measures

Mobile phone numbers and passwords are encrypted for storage and management so that only the individual knows them, and verification and modification of personal information are possible only by the individual who knows the password. Users' personal information is transmitted using an encrypted communication channel, and important information such as passwords is encrypted for storage.

The Company does its utmost to prevent members' personal information from being leaked or damaged by hacking, computer viruses, and the like. To prepare for damage to personal information, data is backed up from time to time, and the latest antivirus programs are used to prevent users' personal information and data from being leaked or damaged.

The Company minimizes the number of employees who handle personal information and reduces the risk of personal information leakage by blocking the use of external internet services on work PCs. It also establishes systematic standards for the creation and modification of passwords and access privileges for the database systems that store personal information and the systems that process it, and conducts ongoing audits.

Administrative measures

The Company limits handling of personal information to designated staff, assigns them a separate password for this purpose, and updates it regularly.

The Company periodically trains its staff and emphasizes the security of the handling and management of users' personal information.

The Company verifies, through its internal personal-information-protection department and the like, the implementation of the Company's Privacy Policy and staff compliance, and strives to correct and rectify any issues immediately upon discovery.

9. Other Matters for Users to Observe

Users have a duty to protect their own personal information, and the Company assumes no responsibility for problems arising from the leakage of personal information caused by the user's own carelessness without fault on the part of the Company, by browser vulnerabilities, or by hacking using methods or technologies that cannot be blocked by security measures under applicable laws, or other problems on the internet that the Company cannot control despite exercising due care.

Users must keep their personal information up to date, and the user is responsible for problems arising from the entry of inaccurate information.

Using the site by stealing another person's personal information may result in loss of membership and punishment under the Resident Registration Act.

Users are responsible for maintaining the security of their ID, password, and the like, and may not transfer or lend them to third parties.

Users must comply with the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Personal Information Protection Act, the Resident Registration Act, and other laws concerning personal information.

10. Scope of Application of the Privacy Policy

The Company may provide links to other websites. In such cases, this Privacy Policy does not apply to the collection of personal information by the linked websites.

11. Contact for the Personal Information Protection Officer and Person in Charge

The Company does its best to ensure that users can use good information safely. Users may report any personal-information-protection complaints arising in the course of using the Company's services to the personal information protection officer or the responsible department. However, the Company is not responsible for damage to personal information caused by unforeseen incidents due to basic network risks such as hacking despite technical remedial measures, or for various disputes arising from posts written by visitors. The Company will respond promptly to users' reports.

[Personal Information Protection Officer]

Name: Lim Young-gwan

Affiliation/Position: Management / CEO

Phone: 070-5213-0924

Email: contactus@imdr.kr

If you need to report or consult on other personal information infringements, please contact the agencies below.

Personal Information Infringement Report Center (http://privacy.kisa.or.kr / 118 without area code)

Privacy Mark Certification Committee (www.eprivacy.or.kr / 02-580-0533~4)

Supreme Prosecutors' Office Cyber Crime Investigation Division (cybercid@po.go.kr / 02-3480-3571)

National Police Agency Cyber Terror Response Center (www.ctrc.go.kr / 02-392-0330)

12. Changes to the Privacy Policy

Where there are changes (additions, deletions, or modifications) to the Privacy Policy, the Company gives notice 7 days in advance through the "Notices" section of the website or application. The Company also discloses the before-and-after comparison so that customers can easily check the changes.

13. Duty of Notification

Where there are changes such as additions, deletions, or modifications to the contents of this Privacy Policy, notice will be given through the website's notices from 7 days before the effective date.

Date of first announcement: November 1, 2024

Date of last revision and enforcement: June 2, 2026